From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Thompson Subject: Re: Support for setuid binaries Date: Wed, 30 Apr 2014 18:26:57 -0400 Message-ID: <87eh0ewj0u.fsf@labrys.i-did-not-set--mail-host-address--so-tickle-me> References: <87a9b25xb2.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:38420) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Wfcy3-0008Vu-PB for guix-devel@gnu.org; Wed, 30 Apr 2014 18:27:14 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Wfcxx-0008K0-44 for guix-devel@gnu.org; Wed, 30 Apr 2014 18:27:07 -0400 Received: from na6sys009bog034.obsmtp.com ([74.125.150.108]:46361) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Wfcxw-0008Jq-Us for guix-devel@gnu.org; Wed, 30 Apr 2014 18:27:01 -0400 Received: by mail-qa0-f53.google.com with SMTP id i13so2318358qae.12 for ; Wed, 30 Apr 2014 15:26:59 -0700 (PDT) In-Reply-To: <87a9b25xb2.fsf@gnu.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org To: Ludovic =?utf-8?Q?Court=C3=A8s?= , guix-devel Ludovic Court=C3=A8s writes: > Hello, > > Commit 09e028f adds support for setuid binaries. Since the store cannot > contain setuid binaries, we use the same technique as NixOS: setuid > binaries are created when booting (or when switching configurations.) > > That is, for each setuid program, a hard link or a copy of the > executable is created under /run/setuid-programs and make setuid-root. > > You can test it by running: > > ./pre-inst-env guix system vm build-aux/hydra/demo-os.scm > > and running for instance =E2=80=98ping=E2=80=99 as guest from there. > > Ludo=E2=80=99. That's great news! I've been missing sudo lately. - Dave